Rolling it out
Move an instance to enforce, and the known limitations
Rolling it out
Move an instance to enforce in steps, watching the log before refusing anything:
- Set
launchValidation: logon the forms launched over REST, orLAUNCH_VALIDATION=logfor the whole instance. - Run in this mode for a while and review the log:
would refusewarnings indicate launches that break the rules;extravars differwarnings indicate forms that compute something differently on the server (a timestamp, outside data). Decide for each form whether that matters. - Switch those forms to
launchValidation: enforce. Callers that sent invalid values or made-up extravars now get a422with the reason. - When every form behaves as expected, consider
LAUNCH_VALIDATION=enforcefor the whole instance.
Limitations
Launch validation does not cover everything yet:
- Wizard forms are not checked yet: a wizard sends its merged step output, not the raw field values, so the server has nothing to validate. Under
enforce, a wizard launch is refused; a wizard form cannot setlaunchValidation. The MCP server cannot launch wizard forms either. - Placeholder resolution in the browser still uses its own copy of the server’s code; in rare edge cases (
__undefined__, quotes inside expressions) the two could resolve a placeholder differently.logreveals such differences. runLocalexpressions run in the browser’s JavaScript engine in the browser and in a sandbox on the server; the same code produces the same result, except where it depends on the browser’s timezone or locale.